To prove who you are, the internet asks you to hand over the proof.
Then it stores it. Then, eventually, it loses it. We have all agreed to this for thirty years, and it is not a failure of anybody's security team. It is the design.
Look at what we agreed to
- You photographed your driver's license and sent it to a stranger, because a website asked.
- You typed your home address into dozens of boxes this year, on a phone, in the dark, at a checkout.
- You have hundreds of passwords and you reuse a handful of them, and you know it. Ninety-four percent of people do, against nineteen billion leaked passwords.1
- A shop you bought socks from in 2019 still holds your card number.
- Every time you prove your age, you hand a company a photograph of your face.
None of that is anyone being careless. It is what happens when the only way to prove something about yourself is to give away the thing that proves it.
The flaw has a name
A reusable secret.
A card number. A social security number. A date of birth, a password, a mother's maiden name. Every one of them has the same property: steal it once, use it anywhere, for years. That is why a single breach at a company you forgot about follows you for the rest of your life, and why identity theft is clerical work rather than a heist: $38 billion taken from 36 million people in a year,2 off the back of a record 3,322 breaches, up 79% in five years.3
We built an economy on secrets that never expire and then acted surprised when they leaked.
Liir solves that with a signature instead of a secret.
Nothing reusable ever reaches the other side.
What actually changes
Your Liir holds a key that never leaves your device. When a site needs something, it asks, and your Liir answers with exactly that and nothing else, signed, once, for that site only. The answer is worthless to anybody who intercepts it and worthless tomorrow.
Today
The shop stores your card, your address, your email, your date of birth. Forever. Everything it holds is worth stealing.
With a Liir
The shop stores a receipt and a shipping label. There is nothing in the database worth stealing, because it was never sent.
- No card number to lose. The merchant never receives one, so no breach can expose it.
- A breach yields receipts. Not identities, not cards, not a list of who lives where.
- Proving your age costs you nothing. No photograph, no document, no company holding your face.
- To be you, someone needs your device and your approval, not a number they can buy for four dollars.
What this does to fraud
Card fraud is an industry because credentials are reusable. Steal a number, use it a thousand times, sell what is left. That is a business model, and it works for one reason: the thing you steal keeps working.
The scale follows from the reusability. Credential theft rose 160% in a single year, 1.8 billion logins lifted from 5.8 million infected machines,6 and breaches that begin with a stolen credential cost an average of $4.67 million each.7
A signature has none of the properties that make that business possible. It is bound to one merchant, one amount, one moment. Steal it and you have a receipt.
And the bigger half, which nobody talks about
Most chargeback losses are not stolen cards at all. They are real customers disputing real purchases they made: $132 billion a year,5 and rising for more than four in five large merchants.8
It works because the merchant cannot prove you approved anything. They hold an IP address and a shipping label. The rules default to the cardholder, correctly, and so "I did not authorize this" is both unfalsifiable and free.
When the approval was signed by a key only you hold, that same sentence becomes something a dispute can actually examine. Not a merchant's word against a customer's. Evidence.
Said carefully
A signature proves your key approved this purchase. It does not prove you meant to, and the space between those two is where the fraud we do not fix lives.
It is not people held at gunpoint. It is scams. Someone is talked into approving by a fake bank, a fake romance, a fake emergency: roughly $3 billion in imposter scams in a year in the United States, tripled since 2022.9 Every one of those is a real person genuinely approving on their own device. A better signature signs a scam perfectly.
And it is closer to home than that. One in four domestic abuse survivors report credit taken out in their name by a partner, without consent or because they were afraid to say no.10 A device you unlock in front of someone who controls you is not a device that protects you.
So here is the uncomfortable part, which belongs on our own page rather than somebody else's. In the United States a person who authorized a payment to a fraudster is usually left holding all of it, and the sentence that keeps them there is but you approved it. We are building a better proof of approval. Pointed the wrong way, that is a better version of that sentence.
Chargeback rights exist in law for good reasons and we are not proposing to take them from anyone. What changes is that a dispute stops being decided by whoever the rules favor by default and starts being decided on what happened. We would rather lose a dispute than help win that one.
Fraud does not disappear.
It stops being scalable.
What is left needs a conversation with one person, on their own device, one at a time. That is a worse business than a database.
Why nobody has done it
Not for technical reasons. The specifications have been published, public and free, for years: the W3C made Verifiable Credentials a Recommendation11 and Decentralized Identifiers a Recommendation12 while the industry carried on emailing photographs of passports to each other.
Identity was always somebody's business model. Signing in with a social account exists so that company learns where you go afterward. The firms with the reach to fix this are funded by precisely the thing fixing it would end. It is not that nobody was clever enough. It is that nobody could afford to.
We charge two dollars a month. That is the entire trick, and it is why this can exist.
It runs where you already are
Your Liir is not an app you have to remember. It lives on your computer, in your browser, on your phone, and on a printed card in a drawer. Most of the time you never point a camera at anything. A site asks, you approve, and it is done.
The questions you are already asking
Credit does. Cards don't. Teen debit accounts start well below eighteen, prepaid cards have no age floor at all, and most checkouts take debit. The internet treats having a card as a stand-in for being an adult, everyone knows it is a poor one, and twenty-seven states have now passed laws because of it.13
A bartender does not need your home address to sell you a beer. Your license tells them anyway: legal name, date of birth, address, height, photograph, all to establish one fact. That is a driving permit that gained a photograph in the 1980s and a barcode in the 1990s,14 now serving as the internet's identity layer. Liir carries the same government verification without the other nine fields.
No. Each purchase is its own artifact, signed once, for that shop, that day. Replay it and you get a receipt with a handle on it, not money.
Those need a standing permission, and you hold the switch. Today, stopping a subscription means asking the merchant nicely or cancelling your card and breaking everything else. Here you withdraw the permission yourself, and they cannot charge you again.
Enroll a second device, the way you already do with passkeys. There is a recovery phrase behind that, and behind that a printed card in a drawer that needs no battery and no network.
Because their checkout has no form and their database has nothing worth stealing. Seven in ten carts are abandoned, and the average American checkout puts 23 form elements in front of somebody who already decided to buy.15 A merchant who never receives a card number also leaves a compliance regime that costs them real money every year.
What this does not fix
It does not make you unphishable. If people are trained to approve without reading, approval becomes the new password, and that is a real failure mode we have to keep designing against for as long as this exists.
It does not help until it is accepted. A better lock on one door does nothing while the other doors still take the old key. The value of this grows with every site that takes it, which means the early years are the hardest ones.
And it is not the last line of defense against anything. Merchants, banks and the law sit in that chain ahead of us. Our job is to make proving something about yourself possible and private. That is all, and it is enough.
Liir means light.
A page is lit or it is not. The mark is beads of it. The heart at the center lights when somebody checked, and stays dark when nobody has. None of that was decoration. Where the word came from ›
A site asks.
It just happens.
or
or read How Liir Works · it is free on your own hardware
Sources
- Password Reuse Statistics 2026 and Password Statistics 2026. A 94% reuse rate against roughly nineteen billion leaked passwords in circulation.
- Javelin Strategy & Research, 2026 Identity Fraud Study, reported in Identity Theft Statistics 2026. $38bn in combined losses across 36 million victims.
- Identity Theft Resource Center, 2025 annual report and Q1 2026 analysis, reported in Identity Theft Statistics 2026. A record 3,322 data compromises in 2025, a 79% rise across five years.
- Chargeflow, Chargeback Statistics 2026. Card-not-present fraud reaching $28.1bn, a 40% rise since 2023, and the $5.13 a US merchant loses for every dollar of fraud.
- Chargeflow, Friendly Fraud: the $132bn chargeback threat. Friendly fraud driving up to 75% of all chargeback losses.
- Recorded Future, credential theft analysis released March 2026, reported in Password Statistics 2026. Credential theft up 160% in a year: 1.8 billion logins from 5.8 million infected hosts.
- IBM, Cost of a Data Breach, reported in Password Statistics 2026. Breaches beginning with a compromised credential average $4.67m each.
- Chargebacks911, Chargeback Stats, and the associated enterprise study. More than 83% of enterprise merchants report friendly fraud rising over the past three years.
- US Federal Trade Commission and Federal Reserve data on imposter scams and authorized push payment fraud, reported in Authorized Push Payment Fraud: Global Trends and Push Payment Fraud Statistics. Around $3bn in US imposter scam losses in a year, roughly tripled since 2022, with US, UK and India losses projected near $5.25bn in 2026. In each case the victim authorized the payment, which is exactly why a signature does not help them.
- Surviving Economic Abuse, What is coerced debt, and Adrienne Adams et al., Michigan State University, reported in Victims of domestic violence often stuck with financial debt. One in four victim-survivors report credit taken out in their name without consent or under fear; of 188 divorcing women studied in Texas, 67% carried coerced debt.
- W3C, Verifiable Credentials Data Model. A published Recommendation. Selective disclosure of signed claims is not a new idea and never was.
- W3C, Decentralized Identifiers (DIDs). A published Recommendation. The identifier scheme this product uses is a standard, not an invention of ours.
- Age Verification Laws by State, following Free Speech Coalition v. Paxton, decided by the US Supreme Court in June 2025. Twenty-seven states had age verification in force as of August 2026; Wyoming's HB 43 carries no content threshold at all.
- AAMVA and Driver's licenses in the United States. Photographs appeared on US licenses in the mid-1980s; machine-readable standardization followed under an AAMVA standard from 1992. There is no national identity card in the United States, which is how a driving permit became the default proof of everything.
- Baymard Institute, Cart Abandonment Rate. A 70.22% average across 50 studies, and an average of 23.48 form elements shown by default in a US checkout.
Where a figure comes from a study we could not read directly, the study is named and the report we did read is linked. Figures are current as of August 2026 and several of them are moving quickly, all in the same direction. If you find one of these wrong, we would rather hear it than keep printing it: hello@liir.net.
Keep reading: Can it be hacked? · What it does to scams · The notary · we can prove when